US8667263B2

System and method for measuring staleness of attestation during booting between a first and second device by generating a first and second time and calculating a difference between the first and second time to measure the staleness

Summary by NHIP

Device Staleness Measurement System

The system measures attestation staleness between two devices by calculating the time difference between an initial boot counter and a current counter. The first device sends sequential requests for booting and current information, which the second device responds to using counters generated by its trusted protection module, basic input/output system, and security portion.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

A method is provided for determining with a first device, staleness of attestation measurements at a second device. The method includes booting up the second device at a first time, the second device having a communication portion, a security portion, a basic input/output system and a trusted protection module. Further, the method includes generating an initial counter based on the booting up of the second device at the first time. A current counter is then generated based on a second time after the first time. The method additionally includes providing a request to the second device from the first device, the request requesting booting information and current information, the booting information being based on the initial counter, the current information being based on the current counter. Still further, the method includes providing a response to the first device from the second device, the response including the booting information and the current information. Finally, the method includes determining, via the first device, the generated initial counter and the current counter based on the response.

US8667263B2, drawing sheet 1
Sheet 1 of 5

Term

5.2 yearsleft in the term

Expires 27 November 2031, including 286 days of term adjustment.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

15 claims: 3 independent, 12 dependent

  1. 1
    Broadest claimClaim Score 42, average(NHIP)A method for determining with a first device, staleness of attestation measurements at a second device, said method comprising:booting up the second device at a first time, the second device having a communication portion, a security portion, a basic input/output system and a trusted protection module;generating an initial counter based on said booting up the second device at the first time;generating a current counter based on a second time after the first time;providing a request to the second device from the first device, the request requesting booting information and current information, the booting information being based on the initial counter, the current information being based on the current counter;providing a response to the first device from the second device, the response including the booting information and the current information;and determining, via the first device, the generated initial counter and the current counter based on the response, wherein said providing a request to the second device from the first device comprises providing a first request and providing a second request, wherein said providing the second request for the current information to the second device from the first device comprises providing a nonce to the second device from the first device, and wherein said providing a response to the first device from the second device comprises providing the response to include the nonce.
  2. 8
    A non-transitory computer-readable media having computer-readable instructions stored thereon, the computer-readable instructions being capable of being read by a computer to be used for determining with a first device, staleness of attestation measurements at a second device, the tangible computer-readable instructions being capable of instructing the computer to perform the method comprising:booting up the second device at a first time, the second device having a communication portion, a security portion, a basic input/output system and a trusted protection module;generating an initial counter based on said booting up the second device at the first time;generating a current counter based on a second time after the first time;providing a request to the second device from the first device, the request requesting booting information and current information, the booting information being based on the initial counter, the current information being based on the current counter;providing a response to the first device from the second device, the response including the booting information and the current information;and determining, via the first device, the generated initial counter and the current counter based on the response, wherein said providing a request to the second device from the first device comprises providing a first request and providing a second request, wherein said providing the second request for the current information to the second device from the first device comprises providing a nonce to the second device from the first device, and wherein said providing a response to the first device from the second device comprises providing the response to include the nonce.
  3. 14
    A device for use with an attester, the attester being operable to transmit a request for booting information and current information, said device comprising:a communication portion operable to receive the request;a basic input/output system having a root of trust measurement portion, said basic input/output system being operable to boot up at a first time, said root of trust measurement portion being operable to generate boot information based on said input/output system booting up;a trusted platform module having a tick counter and a plurality of platform configuration registers, said tick counter being operable to provide a first tickcount corresponding to the first time and a second tickcount corresponding to a second time after the first time;and a security portion, wherein said root of trust measurement portion is further operable to store first information and second information in said plurality of platform configuration registers, the first information being based on the boot information and the first tickcount, the second information be based on the second tickcount, and wherein said communication portion is further operable to transmit a response to the attester based on the first information and the second information, wherein the request includes a nonce, wherein said security portion is operable to generate the response based on the nonce and the first information.